When you run the Microsoft Forefront Online Protection for Exchange (FOPE) Directory Sync Tool (DST), no domains are listed in the Filtering Domains
This occurs if one of the following conditions is true:
- The account that is being used to authenticate does not have sufficient permissions.
- The account that is being used to authenticate has retained legacy permissions from the FOPE Administration Center 8.1 authentication database.
The only permissions that are required to configure the FOPE Directory Sync Tool are Administrator permissions. These permissions must be applied to the domains that you want to synchronize or to the whole organization.
To resolve this issue, add Administrator permissions. Or, remove the legacy permissions and replace with the current Administrator permissions. To do this, follow these steps:
- Sign in to FOPE Administration Center.
- Click Administration, and then click Users.
- Select the user who has the issue.
- Under Permissions, click Remove for the Administrator permission.
- Click Domain, enter your domain, and then click Grant.
- Sign out of the FOPE Administration Center and then sign back in again. You should see the change for the user in the Users list.
- Click Permissions, and then grant the user Administrator permissions at the domain level.
Because the Administrator role supersedes all other roles, you do not have to maintain other roles to perform different tasks in the FOPE Administration Center interface.